Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-dev, 5.42-alpine3.23-dev, 5.42.3-alpine3.23-dev

Index digest:

sha256:ca28a5284025bc36385be4a358ed53724b54f4fb77a18c665d91ec9bee99b617

Manifest digest:

sha256:0854660b454add21dff52997f4b36c1e645b678f30376a63ee84bb499529274b

Size

76.20 MB

Last pushed

2 days ago

Vulnerabilities

0
3
6
0
4

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:ade782d9d058b39513ebbfd789f5a4c5e9551ad22d1e941e309830fe24c96ea5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:cac3385ce409e6ec0fa2a4cee81bc898d9512c6b1f9615577343f59cb61e5451
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:3f7200688bc7d9ae03f039b80588ae29f2dd3da43da12eea996a6c393dea0e95
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:b8e1bff2d36845170b5c188037d431fa3f726be04f5919d2691c3bcfc15e2d78
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:3ac4545e1700838cded9c7ad12aa6871f7dedb1c3e50e89b5ed65372e477ec67
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:f04b70e9a5fa6d18fbfa0834eac5957bb2d7ad920a45f6304115383926517585
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:287504ec0584f228eeb2e44871b823ae47907f4ef44ab8179f3c1e60b230b106
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:ed5c0000b53a406f52104b0fda5a4fdec331361639bdd74d68aca5dcd5f5ef8f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:778924706661713c4889cc4ab4eebaf959428a84cfec7b0d01f0dc034b198b08
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:d2e672b8d075cc0c368fca89632945d77386fdce509b73622018ba0f9a7ed411
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:0c759b95f8d8ddd59f7a3d366433878278d946a6f393a144e21614f999a543db
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:f1f9305e2b6b4470972cee9fa3e5d02057780250feba669dd898d1b48a649dbf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:ea8e4e93739c5c6090c6f7dcef409338b1a743bcca900d8bf3b3dd750ff8ef61
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:ecdb2ac68bc63975d4c71f92c1d32753cae91fd4e2718f197b0aa8ca6f347858
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:74d9b8120ef41a01ee30cb20312c43cd76125a4b8e6fd72afe35ae4b0605f899